1. Introduction
TruIntel ("TruIntel", "we", "us" or "our") is a professional mentorship and upskilling marketplace operated by TW Technology Solutions (Pty) Ltd (registration number 2019/243460/07), a private company incorporated in the Republic of South Africa with its registered office at 74 Rockdale Avenue, Westville, KwaZulu-Natal. This Privacy Policy explains how we collect, use, store, and disclose personal information when you use our website, applications, and services (collectively, the "Services"), whether you use them as a learner, a mentor, an employer sponsor, or a visitor.
We comply with the Protection of Personal Information Act, 2013 (POPIA) of South Africa and, where it applies to our processing, the EU/UK General Data Protection Regulation (GDPR). Nothing in this Policy takes away any right you have under another law that applies to you.
Information Officer (POPIA s 55)
In accordance with section 55 of POPIA, the Information Officer for TruIntel is the head of TW Technology Solutions (Pty) Ltd, being its chief executive officer, or a deputy information officer designated under section 56 of POPIA and registered with the South African Information Regulator. The Information Officer is responsible for ensuring our compliance with POPIA, dealing with requests made to us in terms of the Act, and working with the Regulator in relation to investigations conducted in terms of the Act.
You may contact the Information Officer at quickfix@tw-tech.co.za, or by post at the registered office address listed in section 18.
Right to complain to the Information Regulator
You have the right, at any time and without first contacting TruIntel, to lodge a complaint with the South African Information Regulator regarding our processing of your personal information. The Regulator may be contacted at:
- Email: enquiries@inforegulator.org.za (general); complaints.IR@inforegulator.org.za (complaints)
- Website and complaints portal: https://inforegulator.org.za
EU and UK users may, in addition, lodge a complaint with their local supervisory authority under the GDPR.
2. Data we collect
We collect the following categories of personal information. We collect only what is necessary for the purposes set out in section 3.
Information marked as required at sign-up, verification or enrolment is needed to open your account, verify you, run a booked session or meet a legal duty. If you choose not to supply it, we cannot provide the affected feature: for example, we cannot approve a mentor account without verification evidence, and we cannot process a learnership enrolment without the details the SETA requires. All other information is voluntary.
Account data
- Full name, email address, country of residence, country code
- Timezone and locale
- Date of birth, used for age checks (the Services are for adults of 18 and older)
- Password stored as a salted bcrypt hash (cost factor 12), never in plaintext
- Avatar or profile picture
- Mobile phone number (optional, supplied only if you choose to enable phone or SMS features)
Verification and vetting data
Every account is reviewed and approved by our team before it can transact ("admin vetting"). Depending on your role, verification may include:
- Email and phone confirmation status
- Identity-document type and country of issue; the identity-document number is stored only as a SHA-256 hash, never as the raw number. The hash itself remains protected as personal information
- A selfie or liveness capture supplied through our verification provider (mentors and certain higher-risk activities)
- Professional evidence supplied by mentors: certificates and qualifications, a LinkedIn profile URL, portfolio links, or an introduction video
- The vetting outcome (pending, in review, approved, or rejected), the reviewing administrator, the decision date, and any reason given
- Signup IP address and browser user-agent, captured at registration so that reviewers can identify obvious fraud patterns
Special personal information
Some of the information above is special personal information under section 26 of POPIA and special category data under Article 9 of the GDPR:
- Biometric information. The selfie or liveness capture used to verify your identity is biometric information. We process it only with your explicit consent, which we ask for at the verification step before the camera starts (POPIA section 27(1)(a); GDPR Article 9(2)(a)). If you do not consent, you cannot complete mentor verification, but you can still use the parts of the Services that do not require it.
- Demographic information in statutory learner reporting. Where an accredited programme requires prescribed demographic particulars (for example race or disability status), we process them only to comply with the Skills Development Act, 1998, the National Qualifications Framework Act, 2008 and the applicable reporting standards, which are laws and measures designed to protect and advance persons disadvantaged by unfair discrimination (POPIA sections 27(1)(b) and 29(b)). Where the GDPR applies to you, we rely on your explicit consent (Article 9(2)(a)).
We never use special personal information for marketing, matching or ranking.
Profile data (mentors)
- Headline, biography, hourly rate, introduction video and transcript
- Categories, specialities, skill tags, and session lengths offered
- Verification level, ratings, reviews, and internally computed trust and matching signals (see section 5)
Booking and session data
- Session title, notes for the mentor, scheduled times, duration, status, and pricing (including the commission split applied)
- Refund history and dispute records relating to a session
- Mentor availability schedules and vacation blocks
Payment data
- PayPal account email, PayPal order id, capture id, payout id, and the payer email returned by PayPal
- Bank account details supplied by a mentor who elects EFT withdrawal of earnings
- Transaction amount, currency, status, reference ids, and the wallet ledger (credits, debits, timestamps, external references)
TruIntel does not see, receive, or store card numbers, CVVs, PayPal passwords, or online-banking credentials. All card and bank handling for pay-ins occurs entirely within PayPal's PCI-DSS environment.
Messages and session content
- Chat messages exchanged on the platform and in session rooms (all of which are screened for safety, as described in section 5)
- Whiteboard content, including images a mentor displays during a session
- Session notes and AI-generated study packs and summaries (see section 10)
- Session recordings, only where both participants consent (see section 10)
Skills-development and learnership data (where you take part in an accredited or employer-funded programme)
- Programme and enrolment details: the programme, agreement reference, SETA registration number, start and end dates, funding type, fees, and completion or certification status
- Employer sponsor details: company name, Skills Development Levy (SDL) number, B-BBEE level, and the contact person's name, email address, and phone number
- Workplace logbook entries: attendance, workplace tasks, mentor sessions, assessments, hours, and mentor sign-off records
- Grant and invoicing records relating to the enrolment (tranche amounts, claim status, dates)
Device and telemetry data
- IP address and user-agent string
- Signup IP, last-login timestamp, and security audit logs of significant account actions
- Camera, microphone, and screen-share access (only during a session and only with your explicit browser permission)
Calendar integration data (only when you connect it)
- Encrypted OAuth tokens for Microsoft Graph and Google Calendar
- The provider account id, the OAuth scopes granted, and subscription ids used for webhook delivery
- We do not read the title, body, or attendees of unrelated calendar events
Where we get information about you from someone else
Most information comes from you. We also receive verification results and scores from our identity-verification provider, payment confirmations and the payer email from PayPal, enrolment and sponsorship details from your employer sponsor where it enrols you in a programme, and public professional information from links you give us (for example your LinkedIn profile).
Cookies
See section 11 for the cookies and similar technologies we use.
3. How we use your data
We process your personal information for the purposes set out below. Each purpose is tied to a lawful processing ground under POPIA section 11(1) and the equivalent GDPR Article 6(1) basis.
- Operating your account and delivering the Services. Creating and maintaining your account, matching learners with mentors, scheduling and hosting sessions, running the live session room, and synchronising calendars. Basis: POPIA s 11(1)(b) performance of the contract with you; GDPR Art 6(1)(b).
- Account vetting and identity verification. Reviewing and approving every account before it can transact, verifying mentor identity and professional standing, and maintaining the trust ladder that underpins the marketplace. Basis: POPIA s 11(1)(f) legitimate interests, and s 11(1)(c) compliance with a legal obligation where applicable; GDPR Art 6(1)(f) and 6(1)(c).
- Payments and payouts. Processing session fees through PayPal, applying the published commission model, paying mentors net of commission, refunds, and wallet ledger reconciliation. Basis: POPIA s 11(1)(b); GDPR Art 6(1)(b).
- Trust, safety, and content moderation. Automated screening of platform messages for abusive content and payment circumvention, review of flagged content by authorised administrators, and enforcement of our Terms. See section 5. Basis: POPIA s 11(1)(d) protection of a legitimate interest of data subjects and s 11(1)(f) our legitimate interests; GDPR Art 6(1)(f).
- Skills development, learnerships, and statutory reporting. Administering accredited and employer-funded programmes, maintaining workplace evidence, reporting learner registrations and achievements to the relevant SETA, the QCTO, and the National Learners' Records Database where required, and supporting employer claims (for example Section 12H learnership allowances). See section 8. Basis: POPIA s 11(1)(b) performance of contract and s 11(1)(c) compliance with a legal obligation; GDPR Art 6(1)(b) and 6(1)(c).
- Transactional communications. Welcome and verification emails, booking confirmations, receipts, session reminders, security alerts, and password resets. Basis: POPIA s 11(1)(b); GDPR Art 6(1)(b).
- Marketing communications. Product updates and announcements where you have opted in. Basis: POPIA s 11(1)(a) consent and s 69 (direct marketing); GDPR Art 6(1)(a). You may opt out at any time and every marketing message contains an unsubscribe option.
- Camera, microphone, screen share, and session recording. Enabling live mentorship sessions and, where both parties opt in, recording the session. Basis: POPIA s 11(1)(a) consent; GDPR Art 6(1)(a).
- AI features. Generating session study packs, summaries, and session plans, ranking and matching mentors to learner needs, and supporting the moderation classifiers described in section 5. Basis: POPIA s 11(1)(b) and s 11(1)(f); GDPR Art 6(1)(b) and 6(1)(f).
- Legal and regulatory compliance. Responding to lawful requests, tax and accounting record-keeping, skills-development record-keeping, and enforcing our Terms and Conditions. Basis: POPIA s 11(1)(c); GDPR Art 6(1)(c).
- Analytics and product improvement. Aggregated, where possible de-identified, usage metrics to improve the platform. Basis: POPIA s 11(1)(f); GDPR Art 6(1)(f).
4. Legal basis (POPIA / GDPR)
The table below maps each processing purpose to the relevant lawful ground under POPIA and the equivalent basis under the GDPR. This is a scannable summary; the narrative descriptions in section 3 prevail.
| Purpose | POPIA basis (s 11(1)) | GDPR basis (Art 6(1)) |
|---|---|---|
| Operating your account and delivering the Services | s 11(1)(b) performance of contract | Art 6(1)(b) performance of contract |
| Account vetting and identity verification | s 11(1)(f) legitimate interests; s 11(1)(c) legal obligation where applicable | Art 6(1)(f); Art 6(1)(c) |
| Identity verification biometrics (liveness capture) | s 26 read with s 27(1)(a) explicit consent | Art 9(2)(a) explicit consent |
| Prescribed demographics in statutory learner reporting | s 26 read with s 27(1)(b) and s 29(b) | Art 9(2)(a) explicit consent |
| Payments, payouts, and wallet ledger | s 11(1)(b) performance of contract | Art 6(1)(b) performance of contract |
| Trust, safety, and content moderation | s 11(1)(d) protection of data subjects; s 11(1)(f) legitimate interests | Art 6(1)(f) legitimate interests |
| Learnership administration and SETA / QCTO / NLRD reporting | s 11(1)(b) performance of contract; s 11(1)(c) legal obligation | Art 6(1)(b); Art 6(1)(c) |
| Transactional emails and service notices | s 11(1)(b) performance of contract | Art 6(1)(b) performance of contract |
| Marketing communications | s 11(1)(a) consent; s 69 direct marketing | Art 6(1)(a) consent |
| Camera, microphone, and session recording | s 11(1)(a) consent (browser permission and in-room toggle) | Art 6(1)(a) consent |
| AI study packs, summaries, matching, and moderation classifiers | s 11(1)(b) performance of contract; s 11(1)(f) legitimate interests | Art 6(1)(b); Art 6(1)(f) |
| Tax, accounting, and statutory record-keeping | s 11(1)(c) compliance with a legal obligation | Art 6(1)(c) legal obligation |
| Analytics and product improvement | s 11(1)(f) legitimate interests | Art 6(1)(f) legitimate interests |
Where we rely on consent, you may withdraw it at any time through your account settings or by contacting quickfix@tw-tech.co.za. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
5. Trust, safety & content moderation
TruIntel is a professional community, and we take active steps to keep it safe. You should be aware of the following before you use the messaging and session features:
- Automated message screening. Messages sent on the platform are automatically screened at the time of sending for abusive content, including profanity, hate speech and racism, sexual harassment, and attempts to move payment or contact off the platform. Screening uses curated wordlists and pattern rules, and may additionally use an AI classifier.
- Flag review by administrators. Where the screen detects a potential violation, the message is delivered normally but a moderation flag is created containing the category, severity, and a short excerpt. Flags are reviewed by authorised administrators, who may take account-level action under our Terms. Administrators access message content only for moderation review, dispute resolution, security investigations and legal compliance.
- Automated matching and ranking. We compute internal signals (for example verification level, rating history, and responsiveness) to rank mentors in search results and match them to learner needs. These signals influence ordering and discovery only.
- Human decisions on accounts. Account approvals, rejections, and enforcement actions are taken by a human administrator. We do not make decisions producing legal or similarly significant effects about you by solely automated means; where automated tools assist (for example moderation classifiers), a human reviews the outcome before account-level action is taken.
- Audit logging. Significant account and administrative actions are recorded in an audit log (actor, action, entity, timestamp, IP address) for security and accountability.
6. Who we share data with
We share personal information only with the following categories of recipients, acting either as operators (POPIA terminology) or processors (GDPR terminology) on our behalf, or as responsible parties in their own right (for example PayPal in respect of payment processing, and authorities to whom the law requires disclosure), and only to the extent necessary:
- Other users on the platform. Mentors see learner names, timezones, and the notes attached to booked sessions. Learners see mentor profiles, ratings, and reviews.
- Employer sponsors. Where your participation in a programme is funded or sponsored by your employer or a prospective employer, we share your enrolment status, attendance, workplace logbook evidence, assessment progress, and completion or certification outcome with that sponsor's designated contact.
- Skills-development authorities. Where you take part in an accredited or registered programme, we disclose enrolment, progress, and achievement records to the relevant Sector Education and Training Authority (SETA), the Quality Council for Trades and Occupations (QCTO), and the South African Qualifications Authority's National Learners' Records Database (NLRD), to the extent required by the Skills Development Act, 1998 and related regulation. See section 8.
- PayPal (payments and payouts). The contracting PayPal group entity is the one identified in PayPal's user agreement for your country. We pass your name, email address, the session reference, and the transaction amount. PayPal processes card and bank credentials entirely within its own PCI-DSS-compliant environment, under its own privacy policy, acting as a responsible party in its own right.
- Anthropic, PBC (AI features). For study packs, session summaries, and moderation classifiers, we send prompts containing the relevant content excerpts and session metadata. We do not permit our API content to be used to train the provider's models.
- Amazon Web Services (hosting and email). Our infrastructure is hosted on AWS in the Africa (Cape Town) region, af-south-1, inside the Republic of South Africa. Transactional email is delivered through Amazon Simple Email Service in the same region. Where enabled, S3 storage is used for session recordings, verification evidence, and introduction videos.
- Video infrastructure provider (LiveKit, where enabled). Live session audio and video streams are relayed through our real-time video provider for the duration of the session.
- Microsoft Corporation (Microsoft Graph) and Google LLC (Google Calendar). Only if you explicitly connect Outlook or Google Calendar, and only to read free/busy data and write session invites.
- Identity-verification provider (as configured per environment). Only when you submit identity-verification information. The provider performs document checks and liveness detection and returns a result to us.
- Twilio Inc. (phone verification, where enabled). We share your phone number and the one-time password for delivery.
- Professional advisors. Auditors, lawyers, and accountants under duties of confidentiality.
- Law enforcement and regulators. When legally compelled by a valid court order, subpoena, or statutory request, or where disclosure is necessary to protect life or prevent serious harm.
TruIntel does not sell personal information to any party, and does not engage in surveillance advertising, behavioural ad targeting, or cross-context tracking.
7. Payments & PayPal
All pay-ins are processed by PayPal. We never see, store, or transmit your full card number, CVV, or expiry date. PayPal handles tokenisation and PCI-DSS compliance entirely within its own environment. The information we receive from PayPal is limited to the transaction id, capture id, status, amount, currency, payer email, and (where the funding source is a card) the last four digits of the funding instrument.
Mentor withdrawals are paid via PayPal Payouts or, where the mentor elects it, by EFT to the bank account the mentor supplies. Bank account details supplied for EFT payouts are used only to make those payments and for the associated accounting records.
For the commercial terms applicable to payments and refunds, see the Terms and Conditions.
8. Learnerships & SETA reporting
TruIntel supports accredited and employer-funded skills-development programmes in South Africa, including learnerships and skills programmes within the framework administered by the QCTO and the SETAs. If you enrol in such a programme, the following applies in addition to the rest of this Policy:
- What we process. Your enrolment record (programme, agreement reference, SETA registration number, dates, funding type, fees, status), your workplace logbook (attendance, workplace tasks, mentor sessions, assessments, hours, and mentor sign-offs), your achievement and certification outcomes, and the sponsoring employer's details (company name, SDL number, B-BBEE level, and contact person).
- Statutory disclosures. Learnership agreements are registered with the relevant SETA, and learner registration, progress, and achievement data are reported to the SETA, the QCTO, and the NLRD to the extent required by the Skills Development Act, 1998, the National Qualifications Framework Act, 2008, and their regulations. These disclosures are a legal requirement of participating in an accredited programme and cannot be opted out of while you remain enrolled.
- Employer tax and compliance support. Where your employer claims skills-development incentives (for example the Section 12H learnership allowance) or B-BBEE skills-development recognition, we provide the employer with the enrolment and completion records that substantiate the claim. The employer is responsible for its own submissions to SARS and its verification agencies.
- Additional identity information. Statutory learner reporting may require additional identity particulars (for example an official identity number and demographic information prescribed by the reporting standard). Where this applies, we will tell you at the point of collection, collect only what the standard requires, and protect it in line with section 14. Demographic particulars such as race or disability status are special personal information. We process them only under POPIA sections 27(1)(b) and 29(b), to comply with skills-development laws and measures designed to advance persons disadvantaged by unfair discrimination, and never for any other purpose.
- Retention. Learnership and skills-development records are retained for the period required by the QCTO, the relevant SETA, and tax legislation, which is at least five years after programme completion. See section 12.
9. Calendar integrations
If you connect Microsoft Outlook (via Microsoft Graph) or Google Calendar, we request the minimum OAuth scopes needed to schedule sessions:
- Microsoft Graph:
Calendars.ReadWrite(plusoffline_accessfor token refresh) - Google:
https://www.googleapis.com/auth/calendar.events
These scopes allow us to read your free/busy availability and to create, update, or cancel session calendar events. We do not read the title, body, or attendees of unrelated calendar events.
OAuth access and refresh tokens are encrypted at rest using AES-256-GCM. You can disconnect at any time from Settings; on disconnect we revoke the token locally and, on a best-effort basis, at the provider.
10. Live sessions, recordings & AI study packs
The live session room transmits camera, microphone, and screen-share streams for the duration of your session. We do not record sessions by default.
Recording occurs only where both parties consent in-room. When both the mentor and the learner have consented, the recording is stored encrypted at rest. Access is restricted to the participants in that session and, where necessary for dispute resolution, safety investigations or legal compliance, to authorised administrators, whose access is audit-logged. Recordings are retained for 30 days from the session date and then deleted automatically, unless a participant explicitly elects to save the recording, in which case it is retained for as long as the underlying session record exists.
AI study packs and summaries. Session notes, whiteboard content, and session context may be processed by an AI model to produce a structured study pack for the learner. Packs are marked for human review where the model flags low confidence, and mentors can review packs generated from their sessions.
Whiteboard content and chat messages are stored so that you can revisit them after a session. Messages are subject to the safety screening described in section 5. You can delete conversation content from your dashboard, subject to legal retention requirements and open disputes.
11. Cookies & tracking
We use only the following categories of cookies and similar storage technologies:
- Strictly necessary. The
tw_sidsession cookie used to keep you signed in. This is essential for the Services to function and cannot be disabled. - Strictly necessary. The
tw_csrfcookie, which protects forms and account actions against cross-site request forgery. It contains a random security token, holds no profile information and expires after 24 hours. - Functional. Theme and timezone preferences, stored in your browser's
localStorage(for exampletw.theme). These exist only on your device and are not transmitted to any third party. - Analytics. No analytics cookies are enabled in this release. Should we enable privacy-respecting analytics in future, we will update this section first.
We do not use any third-party advertising cookies, surveillance-advertising pixels, or cross-site tracking technologies. Session cookies are configured as httpOnly, sameSite=Lax, and Secure.
12. Data retention
We retain personal information only for as long as is necessary for the purposes set out in this Policy, or as required by applicable law. Concrete retention periods per category are:
- Account data. Retained for as long as your account exists. On deletion, your account is anonymised immediately: your name, email address, phone number, avatar and identity hashes are removed or replaced and your account is deactivated. Deletion cannot be reversed. Records we must keep by law (for example payment records) are kept without the link to your identity wherever possible.
- Authentication sessions. Session tokens are valid for up to 30 days from issue, and are revoked on logout, password change, or material account event.
- Payment, wallet, and invoicing records. Retained for 5 years from the date of the transaction under the Tax Administration Act, 2011, and for 7 years where the records form part of our accounting records under section 24 of the Companies Act, 2008.
- Chat messages. Retained for 24 months from the date of last activity in the conversation, unless under a legal hold or required for an active dispute.
- Moderation flags. Retained for 24 months from creation, or longer where needed for an enforcement action, an active dispute, or a legal hold.
- Session recordings. 30 days from the session date, then deleted automatically, unless a participant has explicitly saved the recording (see section 10).
- Identity-verification evidence. Retained for 5 years from completion of vetting, then deleted.
- Learnership and skills-development records (enrolments, logbooks, achievements, employer sponsorship records). Retained for at least 5 years after programme completion, or such longer period as the QCTO, the relevant SETA, or tax legislation requires.
- Audit logs. 24 months.
- Cookies. As documented in section 11.
Where a longer period is required to comply with a legal obligation, to establish, exercise, or defend legal claims, or to respond to a regulator, we retain the data for that longer period.
13. Your rights
Under POPIA sections 23 to 25, the GDPR, and equivalent privacy laws, you have the following rights in relation to your personal information:
- Access (POPIA s 23; GDPR Art 15). Request confirmation of the personal information we hold about you and a copy of that information. Access requests are handled in line with section 23 of POPIA, read with the Promotion of Access to Information Act, 2000 (PAIA). Send your request to the Information Officer at the address in section 18 and we will process it in the manner and within the time frames PAIA prescribes.
- Correction (POPIA s 24; GDPR Art 16). Request that we correct or update inaccurate, misleading, irrelevant, or incomplete data.
- Deletion or destruction (POPIA s 24; GDPR Art 17). Request that we delete or destroy personal information that we are no longer authorised to retain, subject to the legal retention obligations in section 12 (including statutory learnership records).
- Objection (POPIA s 11(3); GDPR Art 21). Object on reasonable grounds to processing carried out under legitimate interest, and object at any time to direct marketing.
- Restriction of processing (GDPR Art 18). Ask us to pause processing while a query or correction is being investigated.
- Withdrawal of consent (POPIA s 11(2)(b); GDPR Art 7(3)). Withdraw any consent previously given, at any time, without affecting the lawfulness of prior processing. Note that statutory learnership reporting (section 8) is not consent-based and continues while you remain enrolled.
- Data portability (GDPR Art 20, and insofar as available under POPIA). Receive your data in a structured, commonly used, machine-readable format (typically JSON).
- Not to be subject to solely automated decisions (POPIA s 71; GDPR Art 22). As described in section 5, decisions with legal or similarly significant effect are made with human involvement. You may request human review of any account decision by contacting us.
- Lodge a complaint. With the South African Information Regulator (complaints.IR@inforegulator.org.za) or, if you are in the EU or UK, your local supervisory authority. You may complain to the Regulator at any time and do not need to contact us first.
To exercise any of these rights, send a request to quickfix@tw-tech.co.za. We will respond within 30 days of receipt of a valid request, and we may ask you to verify your identity before disclosing personal information.
14. Security
We maintain technical and organisational measures appropriate to the nature of the personal information we process, as required by POPIA section 19 and GDPR Article 32. These include:
- Password hashing.
bcryptwith a cost factor of 12; passwords are never stored or logged in plaintext. - Token and identifier hashing. SHA-256 hashing of session tokens and identity-document numbers, so the raw values are never persisted.
- Encryption in transit. HTTPS is enforced across the platform, with HTTP requests redirected to HTTPS.
- Encryption at rest. Calendar OAuth tokens are encrypted with AES-256-GCM; recordings and verification evidence are stored encrypted where S3 storage is enabled.
- Hardened sessions. Session cookies are
httpOnly,sameSite=Lax, andSecure; sessions are revocable and expire automatically. - HTTP security headers. Content-type sniffing protection, frame-ancestor restrictions, referrer-policy, and permissions-policy headers are set on responses.
- Signed payment webhooks. Inbound PayPal webhook events are verified against PayPal's signature scheme before being processed.
- Access control and vetting. Administrative functions are role-restricted; every account passes human vetting before it can transact; significant actions are audit-logged with actor, timestamp, and IP.
- Least-privilege infrastructure. Production secrets are held in restricted configuration shielded from web access, and database access is limited to the application account.
If a breach occurs where there are reasonable grounds to believe that your personal information has been accessed or acquired by an unauthorised person, we will notify the South African Information Regulator and affected data subjects as soon as reasonably possible after becoming aware of it, as section 22 of POPIA requires. Where the GDPR applies to the processing, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of the breach (Article 33), and affected users without undue delay where the breach is likely to result in a high risk to them (Article 34).
15. International transfers
Our primary hosting, database, and transactional email run on Amazon Web Services in the Africa (Cape Town) region, af-south-1, inside the Republic of South Africa. Your core account, session, and learnership records are therefore stored domestically by default.
Personal information is transferred outside the Republic only where a specific feature requires it, and only on one or more of the grounds permitted by POPIA section 72:
- you consent to the transfer;
- the transfer is necessary for the performance of the contract between you and TruIntel;
- the recipient is subject to a law, binding corporate rules, or a binding agreement providing an adequate level of protection substantially similar to POPIA, including for onward transfers; or
- the transfer is for your benefit and it is not reasonably practicable to obtain your consent, which you would be likely to give.
The cross-border processors we engage, per feature, are:
- PayPal (payments and payouts; the contracting PayPal group entity identified in PayPal's user agreement)
- Anthropic, PBC (AI study packs, summaries, and moderation classifiers)
- LiveKit, Inc. (live session audio and video relay, where enabled)
- Microsoft Corporation (Microsoft Graph calendar integration, where connected)
- Google LLC (Google Calendar integration, where connected)
- Twilio Inc. (phone verification, where enabled)
- Identity-verification provider (as configured, where an external provider is enabled: document checks and liveness detection during verification)
Each is engaged under contractual terms requiring adequate safeguards (including, where applicable, Standard Contractual Clauses or equivalent transfer mechanisms) consistent with POPIA section 72 and, for EU and UK users, GDPR Chapter V. You may ask us for a copy of the safeguards that apply to a transfer by writing to the address in section 18.
16. Children's privacy
TruIntel is a professional mentorship and upskilling platform intended for users aged 18 and older. We do not knowingly create accounts for, or process the personal information of, children (persons under 18) and we do not direct the Services at children.
POPIA section 34 prohibits the processing of a child's personal information except in the limited cases allowed by section 35, none of which applies to the Services. If we learn that a child's personal information has been collected through the Services, we will delete it promptly. If you believe a child has provided us with personal information, please contact quickfix@tw-tech.co.za.
17. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be notified to you by email and via a banner on the platform at least 14 days before they take effect. The "Last updated" date at the top of this page reflects the most recent revision.
18. Contact us
For privacy queries, access requests, or to exercise any of the rights set out in section 13, please contact us at the addresses below.
- Privacy enquiries and access requests: quickfix@tw-tech.co.za
- Legal notices and contractual matters: quickfix@tw-tech.co.za
- General support: quickfix@tw-tech.co.za
- Postal address: TW Technology Solutions (Pty) Ltd, 74 Rockdale Avenue, Westville, KwaZulu-Natal, Republic of South Africa
- Telephone: 031 279 5700
Information Officer (POPIA s 55). The Information Officer is the head of TW Technology Solutions (Pty) Ltd, being its chief executive officer, or a deputy information officer designated under section 56 of POPIA. The Information Officer may be reached at quickfix@tw-tech.co.za.
Supervisory authority. You may, at any time and without first contacting TruIntel, lodge a complaint with the South African Information Regulator at complaints.IR@inforegulator.org.za or via https://inforegulator.org.za. EU and UK users may, in addition, complain to their local supervisory authority.